From e24da447c1e4597118c5ce5e19fd86830d1567eb Mon Sep 17 00:00:00 2001 From: 4gray <4gray@users.noreply.github.com> Date: Sat, 25 Jul 2026 13:59:16 +0200 Subject: [PATCH] fix(ci): restore green master pipeline (hu locale drift, CodeQL upload) (#1237) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Two independent CI failures on master: 1. `Check i18n drift` failed with 3 keys missing from `hu.json` (`SETTINGS.PLAYER_UP_NEXT_RAIL`, `SETTINGS.PLAYER_UP_NEXT_RAIL_DESCRIPTION`, `PORTALS.UP_NEXT`). PR #1231 added them to every locale, but its branch predates the Hungarian locale merged in #1236, so `hu.json` never got them. Both PRs were green in isolation. The failure also aborted the job before the Tier A/B/C unit suites ran. Added the keys with real Hungarian translations rather than English fallbacks. 2. CodeQL has failed on every master push for days. The analysis itself completes; only the SARIF upload fails with "Resource not accessible by integration" because the workflow has no `permissions:` block and the default token is read-only. Added the standard grant. While in that workflow: bumped `actions/checkout` v3 -> v4 (matches every other workflow here) and dropped the obsolete `git checkout HEAD^2` step — the old template's PR-head trick that current codeql-action handles itself, and the only reason `fetch-depth: 2` was needed. Co-authored-by: Claude Opus 5 --- .github/workflows/codeql-analysis.yml | 19 +++++++++---------- apps/web/src/assets/i18n/hu.json | 3 +++ 2 files changed, 12 insertions(+), 10 deletions(-) diff --git a/.github/workflows/codeql-analysis.yml b/.github/workflows/codeql-analysis.yml index 3359f2dda..104345e48 100644 --- a/.github/workflows/codeql-analysis.yml +++ b/.github/workflows/codeql-analysis.yml @@ -14,6 +14,14 @@ on: schedule: - cron: '0 20 * * 3' +# Required so `codeql-action/analyze` can upload its SARIF results. Without an +# explicit grant the default token is read-only and the upload fails with +# "Resource not accessible by integration". +permissions: + actions: read + contents: read + security-events: write + jobs: analyze: name: Analyze @@ -30,16 +38,7 @@ jobs: steps: - name: Checkout repository - uses: actions/checkout@v3 - with: - # We must fetch at least the immediate parents so that if this is - # a pull request then we can checkout the head. - fetch-depth: 2 - - # If this run was triggered by a pull request event, then checkout - # the head of the pull request instead of the merge commit. - - run: git checkout HEAD^2 - if: ${{ github.event_name == 'pull_request' }} + uses: actions/checkout@v4 # Initializes the CodeQL tools for scanning. - name: Initialize CodeQL diff --git a/apps/web/src/assets/i18n/hu.json b/apps/web/src/assets/i18n/hu.json index 0c491a774..48c3f8f0a 100644 --- a/apps/web/src/assets/i18n/hu.json +++ b/apps/web/src/assets/i18n/hu.json @@ -304,6 +304,8 @@ "WEB_PLAYER_SHARED_CONTROLS_DESCRIPTION": "Az IPTVnator közös vezérlőinek használata a HTML5-, Video.js- és ArtPlayer-lejátszóban.", "PLAYER_AMBIENT_MODE": "Ambient background fill", "PLAYER_AMBIENT_MODE_DESCRIPTION": "Fill the space around the player with a blurred, dimmed poster instead of plain black bars.", + "PLAYER_UP_NEXT_RAIL": "„Következik” epizódsáv", + "PLAYER_UP_NEXT_RAIL_DESCRIPTION": "Széles ablakban a sorozatlejátszó balra kerül, mellette pedig megjelennek a következő epizódok.", "STREAM_FORMAT_DESCRIPTION": "Az alapértelmezett adatfolyam-formátum kiválasztása (Xtream)", "LANGUAGE_DESCRIPTION": "Az alkalmazás nyelvének kiválasztása", "THEME_DESCRIPTION": "Az alkalmazás megjelenési témájának kiválasztása", @@ -960,6 +962,7 @@ "STREAM_URL_COPIED": "Az adatfolyam URL-címe a vágólapra került", "COPY_STREAM_URL": "Adatfolyam URL-címének másolása", "NOW_PLAYING": "Lejátszás alatt", + "UP_NEXT": "Következik", "CLOSE_PLAYER": "Lejátszó bezárása", "ABOUT": "Ismertető", "SEASONS_AND_EPISODES": "Évadok és epizódok",